---
id: CVE-2025-15461
title: A flaw has been found in UTT 进取 520W 1.7.7-180627
summary: >-
  A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects
  the function strcpy of the file /goform/formTaskEdit. Executing a manipulation
  of the argument selDateType can lead to buffer overflow. The attack can be
  execu…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: utt
product: 520w_firmware
affected:
  - 520w_firmware <= 1.7.7-180627
published: '2026-01-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15461'
references:
  - url: 'https://github.com/cymiao1978/cve/blob/main/new/24.md'
    label: cna@vuldb.com
  - url: 'https://github.com/cymiao1978/cve/blob/main/new/24.md#poc'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.339497'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.339497'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.725818'
    label: cna@vuldb.com
  - url: 'https://github.com/cymiao1978/cve/blob/main/new/24.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00894
epssPercentile: 0.57977
ingestedAt: '2026-09-30T23:29:32.530Z'
---

## Overview

A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTaskEdit. Executing a manipulation of the argument selDateType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `520w_firmware <= 1.7.7-180627`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
